Abu Dhabi, AE
Data Protection Officer
About Emirates Global Aluminium
Emirates Global Aluminium is the world’s biggest ‘premium aluminium’ producer and the largest industrial company in the United Arab Emirates outside the oil and gas industry. EGA is an integrated aluminium producer, with operations on four continents from bauxite mining to the production of cast primary aluminium and recycling. EGA employs over 7,000 of these people including more than 1,200 UAE Nationals. EGA operates aluminium smelters in Jebel Ali and Al Taweelah in the United Arab Emirates, an alumina refinery in Al Taweelah, a bauxite mine and associated export facilities in the Republic of Guinea, a speciality foundry in high strength recycled aluminium in Germany, and a recycling plant in the United States.
Data Protection Officer
Legal, Ethics and Business Integrity
JOB PURPOSE:
The Data Protection Officer (DPO) is a senior role with accountability for the EGA Group’s global data protection and privacy programme. The role holder will serve as EGA’s designated DPO in the UAE and in other applicable jurisdictions where EGA operates. This role is central to ensuring robust privacy governance, regulatory compliance, and the protection of personal data across an increasingly complex and geographically diverse organisation.
The DPO provides expert privacy advice to the Board, executive leadership and business units across all EGA Group entities, including existing and future subsidiaries across the globe.
KEY ACCOUNTABILITIES
Strategic Contribution
- Develops and drives EGA’s global data protection strategy in alignment with corporate objectives, with particular focus on building a scalable privacy framework that supports the Group’s growth.
- Promotes a culture of privacy awareness and accountability across all EGA Group entities.
- Provides strategic counsel to EGA on privacy risks, regulatory developments and data protection compliance matters
Leadership
- Manages the Group’s privacy risk profile across all entities, aligning risk management with EGA’s strategic objectives.
- Leads the response to data breaches and privacy incidents, coordinating with relevant business functions and regulators, and providing updates to executive leadership and the Board as required.
- Serves as the primary point of contact for data protection authorities, regulators and data subjects across all relevant jurisdictions.
- Acts as the escalation point for privacy complaints and complex enquiries.
- Establishes and coordinates a network of data protection coordinators across Group subsidiaries to ensure consistent implementation of privacy standards.
Privacy Programme
- Develops, implements and maintains data protection policies, standards and procedures across the EGA Group, ensuring they remain current with legal, regulatory and organisational requirements.
- Evaluates and enhances the data protection framework across all Group entities, identifying compliance gaps and driving remediation
- Establishes and oversees the privacy governance framework, including data mapping, records of processing activities, and third-party vendor assessments.
- Monitors regulatory developments across all relevant jurisdictions, identifying areas requiring attention and advising on necessary adaptations.
- Provides pragmatic, commercially focused privacy advice to business units, legal and commercial teams, including guidance on privacy and security provisions in contracts and vendor agreements.
- Manages data subject rights requests and privacy-related enquiries.
- Leads data protection impact assessments and privacy risk assessments, advising on identified risks and appropriate mitigations.
New Entity Integration
- Leads privacy due diligence for new ventures, acquisitions and joint ventures, identifying data protection risks, compliance gaps and integration requirements.
- Develops and implements privacy integration plans for new entities joining the Group, ensuring alignment with EGA data protection standards and timely remediation of compliance gaps.
- Advises on data transfer and data sharing arrangements, including cross-border transfers and transitional services agreements.
- Collaborates with Corporate Development, Legal and Digital Transformation teams to embed privacy considerations into strategic initiatives.
Responsible AI Oversight
- Provides advisory oversight on the ethical, legal and operational risks associated with artificial intelligence (AI) systems deployed or developed by the EGA Group.
- Advises on responsible AI principles including transparency, fairness, accountability, bias detection and human oversight requirements.
- Collaborates with Digital Transformation, IT and relevant business teams to embed responsible AI principles into AI development and deployment processes.
- Monitors developments in AI regulation globally, including the EU AI Act, advising leadership on compliance implications and organisational readiness
Training and Awareness
- Briefs leadership and the Board’s Audit and Risk Committee on privacy developments, regulatory changes and emerging risks.
- Develops and delivers privacy training programmes, workshops and guidance materials tailored to different audiences across the organisation
External Advisers and Budget
- Manages relationships with external counsel, consultants and service providers, ensuring quality, timeliness and value for money.
- Manages the privacy function’s budget, maximising efficiency while maintaining quality of advice and service.
Professional Development
- Maintains current knowledge of global privacy legislation, regulatory guidance and industry best practices.
- Pursues relevant professional development and maintains any required professional certifications.
External Profile and Thought Leadership
- Builds and promotes EGA’s reputation for privacy excellence, both internally and externally.
- Contributes to thought leadership through industry forums, publications and professional networks.
Stakeholder Management
- Builds strong working relationships with executive leadership, senior management and key stakeholders across business functions to drive the privacy programme.
- Represents EGA in regulatory engagements and maintains relationships with data protection authorities.
AUTHORITY / DECISION MAKING
- Operates with a high degree of independence while keeping the General Counsel and Head of Ethics & Business Integrity informed on material and strategic matters.
- Exercises financial authority in accordance with EGA’s Delegation of Authority.
QUALIFICATIONS & SKILLS
Education and Qualifications:
- Degree in law, information technology, business or a related discipline.
- Professional certification in data protection (e.g., IAPP CIPP/E, CIPP/US, CIPM, CIPT) strongly preferred.
Experience:
- 7-10 years’ experience in data protection or privacy roles, including senior-level experience leading a privacy programme within a multinational organisation operating across multiple jurisdictions.
- Proven track record of managing data breach response and regulatory engagement.
- Experience supporting M&A transactions, including privacy due diligence and post-acquisition compliance integration.
- Experience influencing senior stakeholders and building cross-functional relationships to drive privacy initiatives.
- Expert knowledge of global data protection legislation, including data protection laws in the UAE, EU, and US.
- Extensive knowledge of AI governance principles and the data protection implications of AI systems, including the EU AI Act and emerging AI regulatory frameworks
Skills and Competencies:
- Strong strategic thinking and the ability to translate privacy requirements into practical business solutions.
- Proven ability to build and scale privacy programmes across multiple jurisdictions and business units.
- Ability to handle sensitive and confidential matters with discretion and sound judgment.
- Ability to distil complex privacy issues into clear, actionable advice for non-specialist audiences.
- Strong commercial acumen with the ability to provide pragmatic, risk-based advice.
- Excellent written and verbal communication skills in English, with the ability to engage effectively at Board and executive level.
- Strong understanding of information technology, data architecture and information security principles.
- Self-directed with the ability to exercise independent judgment and drive change across a large organisation.
- Cultural awareness and the ability to operate effectively across diverse geographies and time zones.
Job Segment:
Database, Compliance, Information Security, Risk Management, Data Architect, Technology, Legal, Data, Finance